A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AFVSOCK implementation are caused by wrong locking in net/vmwvsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.13"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:netapp:baseboard_management_controller_500f_firmware:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"fixed": "15.3"
}
]
},
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:netapp:baseboard_management_controller_a250_firmware:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"fixed": "15.3"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "5.10.13"
}
]
}
]
}